๐Ÿ” CVE Alert

CVE-2026-85750

HIGH 7.2

Piwigo arbitrary file read and remote code execution via insecure image processing

CVSS Score
7.2
EPSS Score
0.0%
EPSS Percentile
0th

Piwigo before v16.4.0 is vulnerable to arbitrary file read and remote code execution in image upload handling when using the Imagick library due to insufficient validation and unsafe processing of user-supplied image files. By abusing format confusion (e.g., disguising SVG content as PNG), an attacker can trigger unintended interpretation of embedded SVG elements that reference local files. In more advanced scenarios, the Imagick support for Magick Scripting Language (MSL) may be abused to process attacker-controlled instructions, potentially leading to unauthorized server-side file writes and remote code execution, depending on configuration. This has been patched in 16.4.0.

CWE CWE-20
Vendor piwigo
Product piwigo
Published Sep 25, 2026
Last Updated Sep 25, 2026
Stay Ahead of the Next One

Get instant alerts for piwigo piwigo

Be the first to know when new high vulnerabilities affecting piwigo piwigo are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Piwigo / Piwigo
<= 16.3.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/Piwigo/Piwigo/security/advisories/GHSA-j9q6-q52g-g8jw helx.io: https://www.helx.io/en/blog/advisory-piwigo